My first time posting here, but I’m hoping somebody may be able to assist in pointing me in the right direction.

I’ve got OpenVPN logs going into my log server and there’s a number of events which get logged periodically. They are almost identical except for the last values which I currently assign to individual fields using the kv plugin, but this means I get 9 events each exactly the same except for one field.

I’ll have a look this evening and see if I can work it out! I’d probably need to look at timed end events as they all come through in batches at the same time, so a short timeout should be OK. Never used this plugin so hopefully it’s not too difficult!